Skip to main content

Module gcm

Module gcm 

Source
Expand description

NIST SP 800-38D Galois/Counter Mode.

GHASH is implemented with a branch-free bit-by-bit multiplication in GF(2^128). Table-driven GHASH is faster but indexes memory with key-derived values; the portable backend refuses that trade.

§Nonce discipline

Reusing a (key, nonce) pair under GCM is catastrophic: it leaks the authentication subkey and lets an attacker forge arbitrary messages. The ontology records this as a hard usage constraint (nonce_reuse_consequence: "catastrophic") so an agent selecting GCM is told to pair it with a counter or a random 96-bit nonce under a message limit. See GcmLimits. Indexed loops over fixed-size limb and word arrays are used throughout; they mirror the index algebra in the specifications these routines implement, so needless_range_loop is allowed rather than obscuring the correspondence.

Structs§

Aes128Gcm
SP 800-38D AES-128-GCM.
Aes192Gcm
SP 800-38D AES-192-GCM.
Aes256Gcm
SP 800-38D AES-256-GCM.
GcmLimits
Invocation limits an agent must respect for a single GCM key.

Functions§

ghash_accelerated
Whether GHASH can use the carry-less multiply on this CPU.